<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Basic Troubleshooting for RPC/HTTP Publishing (Exchange 2003)</title>
	<link>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Fri,  5 Sep 2008 05:18:46 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: Luís Barreto</title>
		<link>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-162255</link>
		<pubDate>Thu, 21 Feb 2008 23:22:55 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-162255</guid>
					<description>Hi Dr Tom

I'm a big fan of yours, I like your writing very much, basically because you explain how to do the things and also why they should be that way.
Now, my problem regarding this (as always) comprehensive troubleshooting guide e one simply question:

The last few days I'm trying to configure one of my ISA/Exchange RPC implementations with Single Sign On. I think I've read all the info on this matter on the web, and unfortunately I didn't get the straight answer, although at this time I suspect witch it is...

- Giving 1 ISA 2006 (AD member), 1 Exchange 2003 (witch is also RPC proxy), 1 or 2 public IP, 1 or 2 web listeners, digital certificates, outlook 2003 or 2007 clients, it is possible to publish RPC over HTTP, securely (only to a subset of AD users) without requiring them to type their password to ISA Server?

As I said, at this time, I think the answer is no. But if I'm wrong please point me some directions.

Thank's

Luis Barreto
Portugal</description>
		<content:encoded><![CDATA[<p>Hi Dr Tom</p>
<p>I&#8217;m a big fan of yours, I like your writing very much, basically because you explain how to do the things and also why they should be that way.<br />
Now, my problem regarding this (as always) comprehensive troubleshooting guide e one simply question:</p>
<p>The last few days I&#8217;m trying to configure one of my ISA/Exchange RPC implementations with Single Sign On. I think I&#8217;ve read all the info on this matter on the web, and unfortunately I didn&#8217;t get the straight answer, although at this time I suspect witch it is&#8230;</p>
<p>- Giving 1 ISA 2006 (AD member), 1 Exchange 2003 (witch is also RPC proxy), 1 or 2 public IP, 1 or 2 web listeners, digital certificates, outlook 2003 or 2007 clients, it is possible to publish RPC over HTTP, securely (only to a subset of AD users) without requiring them to type their password to ISA Server?</p>
<p>As I said, at this time, I think the answer is no. But if I&#8217;m wrong please point me some directions.</p>
<p>Thank&#8217;s</p>
<p>Luis Barreto<br />
Portugal
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Brian P</title>
		<link>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-119060</link>
		<pubDate>Thu, 13 Sep 2007 18:40:23 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-119060</guid>
					<description>I've gone through ALL configs over and over again including this checklist: all is OK. HTTPS connections work fine internally. As soon as I test from outside...nothing. Eventually, all connections fail and Outlook goes offline. I have set this up using your tutorial for single exchange publishing (identical!) as well as similar referrals to technet, petri, and others. This is Outlook Anywhere only, not OWA (OWA works when I set it up to test but then remove the policy to focus on RPCoHTTPS). The log shows a failed connection attempt for the RPC/HTTP rule with an HTTP status code of 0x80004005. I've searched everywhere and can only find cryptic info about this and even less as it applies to ISA. Please refer this to an appropriate post if needed. Please help...I'm at wits end. Thank you.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve gone through ALL configs over and over again including this checklist: all is OK. HTTPS connections work fine internally. As soon as I test from outside&#8230;nothing. Eventually, all connections fail and Outlook goes offline. I have set this up using your tutorial for single exchange publishing (identical!) as well as similar referrals to technet, petri, and others. This is Outlook Anywhere only, not OWA (OWA works when I set it up to test but then remove the policy to focus on RPCoHTTPS). The log shows a failed connection attempt for the RPC/HTTP rule with an HTTP status code of 0&#215;80004005. I&#8217;ve searched everywhere and can only find cryptic info about this and even less as it applies to ISA. Please refer this to an appropriate post if needed. Please help&#8230;I&#8217;m at wits end. Thank you.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Tom Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-106773</link>
		<pubDate>Wed, 04 Jul 2007 16:34:02 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-106773</guid>
					<description>Because you're not preauthenticating with ISA Firewall, so all anonymous connections from any user on the Internet (read hackers) can get to your Exchange Server and take advantage of the anonymous connections. But not pre-authenticating at the ISA Firewall, you remove much of the security the ISA Firewall provides.

HTH,
Tom</description>
		<content:encoded><![CDATA[<p>Because you&#8217;re not preauthenticating with ISA Firewall, so all anonymous connections from any user on the Internet (read hackers) can get to your Exchange Server and take advantage of the anonymous connections. But not pre-authenticating at the ISA Firewall, you remove much of the security the ISA Firewall provides.</p>
<p>HTH,<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Nóri</title>
		<link>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-106772</link>
		<pubDate>Wed, 04 Jul 2007 15:48:38 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-106772</guid>
					<description>But I've managed to get this working by specifying All Users. Why does it not work with All Authenticated Users?

Nóri</description>
		<content:encoded><![CDATA[<p>But I&#8217;ve managed to get this working by specifying All Users. Why does it not work with All Authenticated Users?</p>
<p>Nóri
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Tom Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-106665</link>
		<pubDate>Tue, 03 Jul 2007 19:34:27 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-106665</guid>
					<description>You can't. You must use basic authentication to the Web listener.

HTH,
Tom</description>
		<content:encoded><![CDATA[<p>You can&#8217;t. You must use basic authentication to the Web listener.</p>
<p>HTH,<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Nóri</title>
		<link>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-106658</link>
		<pubDate>Tue, 03 Jul 2007 19:14:53 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/06/27/basic-troubleshooting-for-rpchttp-publishing-exchange-2003/#comment-106658</guid>
					<description>But what if I would like to use Integrated Authentication??</description>
		<content:encoded><![CDATA[<p>But what if I would like to use Integrated Authentication??
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
